Arista · VeloCloud Orchestrator
Updated August 4, 2026
Arista VeloCloud Orchestrator contains an OS command injection vulnerability that may allow remote attackers to access privileged internal functionality. This vulnerability is significant as it can be exploited by attackers to gain control of the system and execute malicious commands. The vulnerability poses a risk to the confidentiality, integrity, and availability of the orchestrator and managed data.
If left unpatched, this vulnerability could lead to complete system compromise, allowing attackers to execute arbitrary commands and steal sensitive information. The potential consequences of this vulnerability are severe and could have long-lasting effects on an organization's security posture.
Apply the latest security patch to Arista VeloCloud Orchestrator as soon as possible to prevent exploitation. Ensure that all instances of the orchestrator are updated to the latest version and review security configurations to prevent similar vulnerabilities.